Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-1813. PoCs published by ajann.
AI-analyzed exploit summary This Perl script exploits a blind SQL injection vulnerability in XOOPS Module eCal 2.24 via the 'display.php' file. It extracts username and password hashes from the MySQL user table by injecting a UNION-based SQL query.
Description
SQL injection vulnerability in display.php in the eCal 2.24 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the katid parameter.
Exploits (1)
This Perl script exploits a blind SQL injection vulnerability in XOOPS Module eCal 2.24 via the 'display.php' file. It extracts username and password hashes from the MySQL user table by injecting a UNION-based SQL query.